Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
1
1
1
Contributors
3
Categories
2
1
1
1
1
Platforms
1
1
1
1
Products / Services
3
1
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
This rule detects unauthorized or anomalous file modifications or creations to machine learning training datasets (e.g., fine-tuning data, training corpora) by users not belonging to the authorized data engineering group, occurring within one hour of a scheduled training or fine-tuning job execution. This behavioral pattern is indicative of potential data poisoning, where an adversary attempts to inject malicious data into the training set to bias or compromise the resulting model.
Detects anomalous data mutations in machine learning training pipelines, such as bulk insertions or label distribution shifts, performed by low-reputation or untrusted contributors. This activity is indicative of attempts to poison model training data to induce backdoors or skew decision boundaries.
Detects potential training data poisoning attempts by monitoring anomalies in ingestion volume, shifts in label distribution, and high-volume submissions from feedback channels. This rule uses statistical analysis to identify spikes in data input or abnormal distributions that deviate from established historical baselines.
